home.social

#vdp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vdp, aggregated by home.social.

fetched live
  1. RE: infosec.exchange/@patrickcmill

    Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers

    cisa.gov/resources-tools/resou

    Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for triaging, remediating and assigning Common Vulnerabilities and Exposures (CVE) identifiers to reported vulnerabilities. The guidance also provides considerations for leveraging third-party intermediaries, like CISA or other national computer security incident response teams, to substitute or supplement a CVD program. By implementing a robust CVD program aligned with this guidance, organizations can work transparently and collaboratively with security researchers to remediate vulnerabilities, build constructive relationships, enhance product security while improving vulnerability management processes, and demonstrate their dedication to protecting customers.

    cisa.gov/sites/default/files/2

    #security #research #CVD #VDP #NSA #CISA

  2. Four fairs combine for inaugural WineMainz event

    Home News By Hamish Graham Published:  12 March, 2026 Germany is set to gain a fresh event for its domestic wine industry, with four existing wine fairs coinciding for the first ever WineMainz event this April. The celebration of German wines will …
    #dining #cooking #diet #food #GermanWine #biodynamic #Germanwine #germany #Mainze #Sekt #VDP #Wine #WineMainz
    diningandcooking.com/2551721/f

  3. #Mathieu #VdP gaat bij zijn allereerste deelname aan de #omloop meteen winnen.

  4. 🇧🇩 Today I'm going to talk about Bondstein Technologies Limited, a company based in Dhaka, Bangladesh. One of their servers was found to be completely open and unprotected.

    Bondstein Technologies Limited is a Dhaka-based technology company specializing in Internet of Things (IoT) solutions and frontier technologies. Founded in 2014, it has established itself as a leading player in Bangladesh for vehicle tracking, industrial automation, and smart connectivity.

    What data was exposed?

    On December 26, 2025, I discovered that the server was exposing a 22 GB SQL backup file. According to the file timestamps and metadata, this backup appears to have been publicly accessible since at least July 2025.Among the files in the backup was users.sql, which contained the following sensitive fields:

    username, customer_name, First_name, Last_name, Phone_number, Additional_contact-number, email, password.

    *I was able to confirm that some of the employee names were real.

    Additional findings:

    The exposed server's IP resolved to a properly certified HTTPS server using a subdomain under .bondstein.net. The same IP also hosted a login portal (which I did not attempt to access).With this information, we were able to accurately identify the owner and submit a responsible disclosure.

    Notification:

    All of this was detailed in the email I sent to several Bondstein employees on December 26, 2025. When I checked again on January 5, 2026, the exposure had been fully closed. I followed up via email to inquire about any possible reward. On January 6, they replied with the following message:

    Hi Chum1ng0,

    Thank you for your responsible and detailed disclosure regarding the open directory issue on our server. We sincerely appreciate you taking the time and effort to notify us of this vulnerability, which allowed us to address it quickly. Your commitment to ethical research is truly valued. We want to confirm that the issue has been fixed and access has been restricted. We would also like to clarify that the server you identified is a staging server kept for internal purposes, and not a production environment. Regarding your request for a reward, we currently do not have an official bug bounty program in place. However, we are grateful for your help in securing our infrastructure.

    We appreciate your patience and look forward to potentially collaborating in the future should we establish a formal program.

    Sincerely
    Bondstein

    -NOT REWARD-

    #VDP #responsibleDisclosure #misconfigurations #Bangladesh #cybersecurity #bondstein

  5. Hey! We just updated platforms.disclose.io with 25+ new bug bounty & VDP platforms! 🎯

    Notable additions:
    • Web3: @Cantinaxyz @CodeHawks @CertiK @xyz_remedy
    • Russia: @standoff365 @bizone
    • Asia: @IssueHunt (Japan), @patchday_io (Korea), Butian (China)

    The ecosystem keeps growing. Check out the full list: platforms.disclose.io

    #BugBounty #VDP #Cybersecurity

  6. Video ~ Armed Men Kill Over 200 People In Burkina Faso ~ OsazuwaAkonedo

    Armed Men Kill Over 200 People In Burkina Faso ~ OsazuwaAkonedo #Algeria #Andriy #Barsalogho #BurkinaFaso #Gourma #Ibrahim #Kidal #Mali #Mansila #Niger #Russia #Sahel #Sebba #Solhan #Tadaryat #Traore #Ukraine #VDP #Wagner #Yagha #news Published: August 26th, 2024 Reshared: August 26, 2024 8:04 am Over 200 people believed to be mostly villagers in Barsalogho municipality of Burkina

    osazuwaakonedo.news/video-arme

  7. Ok, given that the test for this board has been a (painful) success, I am releasing the #TK2000 #VDP board for everyone to enjoy!

    For those that just tuned in, it adds a TMS9918A to your TK2000 home computer.

    Why?
    Because why not!

    codeberg.org/hkzlab/TK2000_VDP

    This project was sponsored by #PCBWay , that kindly printed the boards for me, and they turned out great!

    That said, components and consumables are not free, so every credit you might wish to send me at ko-fi.com/hkzlab is going to be greatly appreciated! ☕

  8. Friday read: Maxime’s push to simplify German wine classification

    Home News By Barnaby Eales Published:  20 September, 2019 In anticipation of the biggest reforms to German wine law in almost 50 years, Rheinhessen vintners are calling for a simpler app…
    #dining #cooking #diet #food #GermanWine #classification #DWI #Germanwine #germany #JohannesGeil-Bierschenk #Maxime #Rheinhessen #VDP #Wine
    diningandcooking.com/2250569/f

  9. "Both Kerckhoffs and Shannon were pioneers of “disclosure thinking”. They both understood that any system needed to be constructed under the assumption that it had already been broken."

    computerweekly.com/opinion/Why

    #bugbounty #vdp #builitlikeitsbroken #cybersecurity
    cc: @Bugcrowd

  10. Vulnerability data is transmitted to CISA, which collects it for further review and resolution of important security issues. 

    #CISA #cybersecurity #USA #VDP

    cybersec84.wordpress.com/2023/

  11. #Abendessen #CozinhaPortuguesa #Cataplana in Deutschland ist es ein Luxusessen - "Cataplana de mariscos" mit reichlich #Venusmuscheln,
    #Seeteufel, #Kabeljau #Tintenfisch und  #Garnelen.

    Dazu fränkischer Wein:
    2019 Sulzfelder Berg 1. Riesling《Steinriegel》#VDP
    Weingut Zehnthof Luckert.